Description
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, querying a readable collection with a relationship to another collection can expose information about related documents protected by access.read where constraints. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Published: 2026-10-06
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized data exposure via relationship queries
Action: Patch
AI Analysis

Impact

Payload CMS, an open‑source headless content‑management system, has an authorization bypass that occurs when querying a readable collection that contains a relationship to another collection. The query can expose information about related documents protected by an access.read constraint, allowing an attacker to read data they should not have access to. This flaw is an example of missing or inadequate access control, as identified by CWE‑862.

Affected Systems

Organizations using Payload CMS should review the affected versions. The vulnerability exists in all releases prior to 3.90.0, as well as all canary builds before 4.0.0‑canary.34. The fix was delivered in Payload CMS 3.90.0 and 4.0.0‑canary.34 and later.

Risk and Exploitability

The CVSS score is 6.9, indicating a moderate level of severity. No EPSS data is available, and the issue is not listed in the CISA KEV catalog. The likely attack vector is a standard API request to the collection endpoint; an attacker who can read the source collection can retrieve data from related collections that are otherwise restricted. Successful exploitation would lead to unauthorized disclosure of protected documents, but it does not allow execution, modification, or denial of service.

Generated by OpenCVE AI on October 6, 2026 at 18:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Payload CMS to the patched release 3.90.0 or later.
  • If you cannot upgrade immediately, modify or remove relationship fields in collections that include protected data, and enforce strict access.read constraints on the related collections.
  • Adjust any custom middleware or API code that accesses collections with relationships to check read permissions before returning related data.

Generated by OpenCVE AI on October 6, 2026 at 18:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-7c34-32v3-j575 Payload relationship-query authorization bypass
History

Tue, 06 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, querying a readable collection with a relationship to another collection can expose information about related documents protected by access.read where constraints. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Title Payload relationship-query authorization bypass
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T17:22:49.268Z

Reserved: 2026-10-05T23:06:29.748Z

Link: CVE-2026-105852

cve-icon Vulnrichment

Updated: 2026-10-06T17:22:45.038Z

cve-icon NVD

Status : Received

Published: 2026-10-06T17:17:20.990

Modified: 2026-10-06T18:16:48.610

Link: CVE-2026-105852

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T18:15:04Z

Weaknesses